logo svg
logo

August 31, 2026

Updated: August 31, 2026

Salt Typhoon: Inside China's Telecom Espionage Campaign

How a China-linked APT reached inside the US telecom backbone, and the wiretap system built for American investigators.

Abdalla Mohamed

Featured Image

Salt Typhoon is the China-linked state-sponsored hacking group behind what a US senator called the worst telecommunications hack in American history. Over several years it burrowed into the core networks of AT&T, Verizon, T-Mobile, Lumen, and at least half a dozen other US carriers, and, most alarmingly, into the lawful-intercept systems the US government requires telecoms to build for court-authorized wiretaps. That access let it pull call records, geolocate people, and target the communications of senior US political figures. This guide explains what Salt Typhoon is, how the attack worked, who it hit, how the FBI and CISA responded, where the IOCs live, and how it differs from its infrastructure-focused sibling, Volt Typhoon.

Updated: August 2026. Reflects the joint CISA/FBI/NSA advisory AA25-239A (August 2025), the confirmed telecom victims, and Salt Typhoon's continued activity into 2025-2026.

The quick answer

QuestionShort answer
What is it?A PRC (Chinese) state-sponsored APT, linked to the Ministry of State Security (MSS)
What did it do?Breached US and global telecoms to intercept calls, texts, and metadata
Who did it hit?AT&T, Verizon, T-Mobile, Lumen, and others; at least 200 US organizations and around 600 worldwide
The scariest part?It accessed the CALEA lawful-intercept (wiretap) systems and targeted political figures' comms
How did it get in?Mainly by exploiting unpatched Cisco network devices and living in the routers
Is it still active in 2026?Yes. It remains active and hard to fully evict

The one line to remember: Salt Typhoon turned the wiretap system the US built for its own investigators into a listening post for Chinese intelligence.

What is Salt Typhoon?

Salt Typhoon is an advanced persistent threat (APT) group attributed to the People's Republic of China, assessed to operate under the Ministry of State Security (MSS) through a network of contractors and front companies. It has been active since at least 2019-2021. "Salt Typhoon" is the name Microsoft assigned it under its weather-themed naming scheme for Chinese state actors; other vendors track overlapping activity as OPERATOR PANDA, RedMike, UNC5807, GhostEmperor, and Earth Estries. In their August 2025 advisory, the US and allied agencies declined to endorse any single commercial name and simply called the actors "APT actors."

Where its sibling Volt Typhoon pre-positions to disrupt infrastructure, Salt Typhoon is a classic, if enormous, espionage operation. Its goal is intelligence: who is talking to whom, from where, and, where possible, the content of those communications.

How the Salt Typhoon attack worked

How the Salt Typhoon attack worked

The campaign was patient and methodical, and it turned on a simple weakness, unpatched network hardware, then escalated into the heart of the telecom.

Who Salt Typhoon hit

The victim list reads like a directory of the US communications backbone, and it extends worldwide.

Victim categoryExamples
US telecom carriersAT&T, Verizon, T-Mobile, Lumen, Charter/Spectrum, Consolidated Communications, Windstream, Viasat
Global telecoms/ISPsProviders across Europe and the Indo-Pacific
Other sectors (per CISA)Government, transportation, lodging (hotels), and military networks
High-value individualsCommunications of senior US political figures, including Donald Trump, JD Vance, and Kamala Harris campaign staff

According to the FBI and the August 2025 advisory, the campaign compromised at least 200 US organizations, and by FBI estimates around 600 organizations worldwide across more than 80 countries. The targeting of hotels and transportation is telling: combined with call and location data, it lets Chinese intelligence identify and track the movements and communications of targets around the world. The specific breaches of Verizon and T-Mobile drew particular attention, though both, along with other carriers, later stated they had evicted the actors from their networks.

The FBI and CISA response

The scale of Salt Typhoon triggered an extraordinary international response.

Salt Typhoon IOCs and detection

For defenders, the single most useful artifact is CISA's advisory itself. AA25-239A ships a downloadable, machine-readable list of indicators of compromise (IOCs) in JSON, alongside detection and threat-hunting guidance. Rather than reproduce volatile indicators here (they change, and stale IOCs create false confidence), the right move is to pull the current list directly from CISA and feed it into your detection stack. The advisory's TTP mapping to MITRE ATT&CK is the more durable resource: hunt for the behaviors, unexpected router configuration changes, GRE tunnels, anomalous administrative access to network devices, and unusual traffic to and from edge infrastructure, not just static indicators.

Salt Typhoon vs Volt Typhoon

Salt Typhoon vs Volt Typhoon

The two headline Chinese "Typhoon" groups are easy to confuse and do opposite jobs. The contrast is the clearest way to understand each.

Salt TyphoonVolt Typhoon
Primary goalEspionage, intercept communicationsPre-position to disrupt critical infrastructure
Main targetsTelecom and ISP backbones, government, lodgingEnergy, water, transportation, comms (incl. Guam)
Signature moveRouter exploitation, tapping wiretap systems, rootkitsLiving off the land, SOHO-router botnet, OT pivot
Value of stolen dataMassive: calls, texts, metadata, wiretap targetsLimited (it's not really spying)
Governing CISA advisoryAA25-239A (2025)AA24-038A (2024)

In one line: Salt Typhoon listens; Volt Typhoon prepares to break things. We cover the disruptive, infrastructure-focused sibling in our Volt Typhoon analysis, compare them directly in Salt Typhoon vs Volt Typhoon, and both sit within the wider nation-state threat picture in the most notorious hackers.

Salt Typhoon in 2026: current status

Salt Typhoon has not stopped. Threat-intelligence reporting through 2025 documented continued exploitation of vulnerable Cisco devices at telecoms and other organizations, and a separate 2024 intrusion into a US National Guard network reportedly went unnoticed for roughly nine months. Carriers have announced they evicted the actors from their networks, but for a group that lives inside routers and trusted connections, "evicted" is a claim that requires continuous verification. As of 2026, Salt Typhoon remains one of the most capable and active espionage threats to global communications infrastructure.

How to defend against Salt Typhoon

The campaign succeeded on fundamentals, unpatched edge devices and weak network-device hardening, so the defense is fundamentals done rigorously.

ControlWhat it addresses
Patch internet-facing network devices urgentlyCloses the Cisco/Ivanti/Fortinet flaws used for initial access
Harden and monitor network-device configsDetects the router modifications used for persistence
Disable unused management services (e.g. Smart Install, web UIs)Removes the exact features exploited by CVE-2018-0171 and CVE-2023-20198
Centralized logging for network infrastructureMakes long-dwell router-level activity visible
Encrypt communications end to endLimits the value of intercepted traffic
Ingest CISA AA25-239A IOCs and hunt the TTPsTurns the joint advisory into active detection
Network segmentation and least privilegeSlows lateral movement through trusted connections

Two priorities dominate. First, treat network devices as crown-jewel assets: patch them on the KEV timeline, disable legacy management features, and monitor their configurations, an extension of the discipline in our patch management guide. Second, assume the perimeter can be turned against you: the whole campaign hinged on exposed, exploitable edge devices, which is exactly what external penetration testing is built to find, and a rehearsed incident response plan determines how fast you can respond when it is.

Why this matters for security teams

Salt Typhoon is a lesson in where modern espionage actually lands: not on endpoints, but in the network fabric, the routers, edge devices, and trusted connections that most security programs under-monitor. It also punctures the assumption that a nation-state needs zero-days: much of this ran on known, unpatched vulnerabilities in internet-facing gear. For any organization, and especially telecoms, ISPs, and their suppliers, the message is that your network devices are a primary target, your patch cadence on them is a national-security-grade control, and "we removed them" is a hypothesis to keep testing, not a conclusion.

DeepStrike's penetration testing probes the exposed network devices and edge services a group like Salt Typhoon exploits, validates whether an attacker could gain and hold access, and gives you the fixes and detections you need. For US-based teams, see our US penetration testing services.

FAQ

What is Salt Typhoon?

Salt Typhoon is a Chinese state-sponsored hacking group, linked to the Ministry of State Security, that conducted a large-scale espionage campaign against telecommunications providers. It breached major US carriers including AT&T, Verizon, and T-Mobile to intercept calls, texts, and metadata, and reached the lawful-intercept systems used for court-authorized wiretaps.

Which companies did Salt Typhoon hack?

Confirmed and reported US telecom victims include AT&T, Verizon, T-Mobile, Lumen, Charter/Spectrum, Consolidated Communications, Windstream, and Viasat, along with telecoms in Europe and the Indo-Pacific. In total, the campaign is assessed to have compromised at least 200 US organizations, and by FBI estimates around 600 organizations worldwide across more than 80 countries, spanning telecom, government, transportation, and lodging.

What is the CISA advisory on Salt Typhoon?

Advisory AA25-239A, published in August 2025 by CISA, the FBI, the NSA, and more than a dozen allied governments, details the tactics, techniques, and procedures of the Chinese state-sponsored actors behind the Salt Typhoon activity. It provides mitigation guidance and a downloadable list of indicators of compromise (IOCs) for threat hunting.

How did Salt Typhoon breach the telecom companies?

It primarily exploited vulnerable, internet-facing network devices, especially Cisco gear via flaws like CVE-2023-20198, CVE-2023-20273, and the older CVE-2018-0171 (Smart Install). It then modified routers to persist, used implants such as GhostSpider and the Demodex rootkit, and pivoted through trusted connections into telecom core and lawful-intercept systems.

Why is the Salt Typhoon hack considered so serious?

Because it compromised the communications backbone and the wiretap infrastructure itself. Access to lawful-intercept systems could reveal which people US law enforcement is surveilling, and the actors targeted the communications of senior political figures. It effectively turned a system built for US investigators into a surveillance tool for Chinese intelligence.

What is the difference between Salt Typhoon and Volt Typhoon?

Both are Chinese state-sponsored groups, but Salt Typhoon is an espionage operation focused on intercepting communications from telecoms, while Volt Typhoon pre-positions inside energy, water, and transportation infrastructure to enable disruptive attacks in a future conflict. Salt Typhoon listens; Volt Typhoon prepares to break things.

Where can I find Salt Typhoon IOCs?

CISA advisory AA25-239A includes a downloadable, machine-readable IOC list in JSON, plus detection and threat-hunting guidance mapped to MITRE ATT&CK. Because indicators change over time, pull the current list directly from CISA and prioritize hunting for the behaviors, such as unexpected router configuration changes and anomalous access to network devices, over static indicators alone.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us